8.5
CVE-2026-102294
- EPSS 0.92%
- Veröffentlicht 01.10.2026 17:30:19
- Zuletzt bearbeitet 02.10.2026 04:18:03
- Erkennungen
Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration
TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTP-Link System Inc.
≫
Produkt
TL-WR841N v14
Default Statusunaffected
Version
0
Version <
4.19 Build 260821 (EN)
Status
affected
Version
0
Version <
4.19 Build 260820 (US)
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.92% | 0.59 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| f23511db-6c3e-4e32-a477-6aa17d310630 | 8.5 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware
https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware
https://www.tp-link.com/us/support/faq/5320/